CVE-2025-32316
BaseFortify
Publication date: 2025-09-05
Last updated on: 2025-09-08
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| android | 16.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in gralloc4 is caused by a missing bounds check that can lead to an out of bounds write. This flaw may result in local information disclosure without requiring any additional execution privileges or user interaction.
How can this vulnerability impact me? :
The vulnerability can lead to local information disclosure, meaning sensitive information on the affected system could be exposed to an attacker with limited privileges. However, it does not allow for execution of arbitrary code or system availability impact.